Boggy Serpens (MuddyWater) AI-Enhanced Cyberespionage Campaign Deploying Nuso, LampoRAT, BlackBeard, Phoenix, and UDPGangster Malware — Threadlinqs Intelligence
As of 2026-05-30, Boggy Serpens (MuddyWater) AI-Enhanced Cyberespionage Campaign Deploying Nuso, LampoRAT, BlackBeard, Phoenix, and UDPGangster Malware is a high-severity apt threat attributed to MuddyWater (Iran), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 53 indicators of compromise.
Threat ID: TL-2026-0238 · Severity: HIGH · Status: ACTIVE · Category: APT
Attribution: MuddyWater · Iran · ESPIONAGE
Iranian threat group Boggy Serpens (MuddyWater), a subordinate element of Iran's Ministry of Intelligence and Security (MOIS), has launched an extensive AI-enhanced cyberespionage campaign spanning
Boggy Serpens, tracked by Palo Alto Networks Unit 42 as an Iranian state-sponsored threat actor subordinate to the Ministry of Intelligence and Security (MOIS), has significantly evolved its cyberespionage operations in a campaign running from August 2025 through February 2026. Active since at least 2017 and also known as MuddyWater, the group has shifted from its historical reliance on legitimate remote monitoring and management (RMM) tools like Atera, ScreenConnect, and SimpleHelp toward deploying custom-built malware families with sophisticated capabilities.
The campaign introduces six distinct malware families representing a major leap in tooling sophistication:
**Nuso (HTTP_VIP)** — A custom HTTP backdoor that uses dynamic API resolution to avoid Import Address Table (IAT) inspection. Commands are delivered via HTTP status codes: 201/204 trigger shell command execution, 210/222 update beacon intervals, and 350/404 signal termination. Data exfiltration occurs through bit-rotated custom HTTP headers (X-Computer-Name, X-Username). PDB paths containing the username 'nuso' and anti-analysis strings ('fuckAnalyzor') reveal developer artifacts.
**LampoRAT (Olalampo/CHAR)** — A Rust-based remote access trojan that masquerades as Kaspersky antivirus (avp.exe) with embedded Kaspersky metadata strings. It uses the Telegram Bot API for command and control with a hardcoded bot token, enabling malicious traffic to blend with legitimate encrypted HTTPS communications. The malware supports shell execution via cmd.exe and directory navigation. Notably, its use of emoji-based status indicators (checkmarks, crosses) in reporting strongly suggests AI-assisted code generation, as large language models frequently include such visual indicators by default.
**BlackBeard** — A Rust-based backdoor tracked by the Israeli National Cyber Directorate. It communicates with stratioai[.]org using the reqwest HTTP crate and encrypts exfiltrated system data with AES-256-GCM (hardcoded key and IV). HTTP response codes 201/202 trigger payload drops to C:\ProgramData\WebDeepPlayer.scr, while 418 signals exit. BlackBeard achieves persistence through a novel technique: registering a custom .wdlp file association in the registry (HKCU\Software\Classes\.wdlp) that triggers WebDeepPlayer.scr execution, combined with dropping Oregon.wdlp in the startup folder. It also scans %PROGRAMDATA% for 15+ security products to fingerprint the target environment.
**Phoenix v4 (Mononoke)** — The evolution of the group's established Phoenix backdoor family. It employs property-based payload encapsulation in VBA UserForm1.TextBox1 controls, hex-shift rotation cipher decryption, and a drop-rename-execute workflow (writing payloads as .log or .txt files before renaming to .exe). Phoenix implements both WMI (Win32_Process.Create) and Windows API (CreateProcessW) execution to decouple from Office parent processes, evading parent-child process monitoring. It includes a brute-force CPU stalling function executing 100+ million operations to timeout automated analysis tools.
**UDPGangster** — A lightweight backdoor using a custom UDP-based C2 protocol on non-standard ports (1269/1259). It features anti-analysis detection of research environments and delivers commands via byte prefixes (0x0A for named pipe creation). Reconnaissance capabilities include nslookup, ipconfig, dir, and Quser commands. Live operator interaction was observed approximately 12 hours post-infection at ~17:00 Iranian time. Distinct PDB path usernames (gangster, piper, surge) map to specific target sectors: Israel aviation, Azerbaijan finance, and Israel telecom respectively.
**GhostBackDoor** — A newly documented advanced implant enabling remote control and file access, deployed via personalized social engineering lures.
The campaign's initial access vector consistently relies on spear-phishing with malicious macro-enabled Office documents distributed from compromised legitimate accounts, including Omani Min
Target sectors: government, military, energy, maritime, aviation, telecom, finance, critical-infrastructure
Target regions: Middle East, Israel, UAE, Saudi Arabia, Turkey, Oman, Egypt, Azerbaijan, Turkmenistan, Hungary, Europe, Central Asia
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 53 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, T1587, T1586, T1566, T1199, T1204, T1059, T1047, T1106, T1547, T1546